1) All versions of Shorewall-perl mishandle per-IP rate limiting in REDIRECT and DNAT rules. The effective rate and burst are 1/2 of the values given in the rule. Corrected in 4.4.7.1